T09 · Insecure Skill Coding Practices
- Location
scripts/md2pdf.sh:78- Finding
Untrusted Markdown Is Compiled with Raw LaTeX Enabled
- Content
View full analysis
/g' \ > "$TMPDIR/input.md" ``` ```bash # --- Build pandoc command --- PANDOC_ARGS=( "$TMPDIR/input.md" -o "$OUTPUT" --pdf-engine=xelatex -f markdown-smart -H "$HEADER_FILE" -V "mainfont=$MAIN_FONT" -V "sansfont=$MAIN_FONT" -V "monofont=$MONO_FONT" -V "geometry:margin=$MARGIN" -V "fontsize=$FONT_SIZE" -V colorlinks=true -V linkcolor=blue -V urlcolor=blue --highlight-style="$HIGHLIGHT" ) if [ -n "$TOC" ]; then PANDOC_ARGS+=($TOC -V "toc-title=$TOC_TITLE") fi # --- Run pandoc --- echo "Converting: $INPUT -> $OUTPUT" >&2 echo " Engine: xelatex | Font: $MAIN_FONT | Mono: $MONO_FONT | Size: $FONT_SIZE | Margin: $MARGIN" >&2 pandoc "${PANDOC_ARGS[@]}" 2>&1 | while IFS= read -r line; do ``` ### Technical Analysis The script accepts a caller-supplied Markdown file and processes it with Pandoc's `markdown` reader before compiling the resulting document through XeLaTeX. The selected input format, `markdown-smart`, does not disable Pandoc's raw TeX extension. Raw LaTeX embedded in the source Markdown can therefore be preserved and evaluated by XeLaTeX. The sanitization stage only replaces a fixed set of emoji, smart quotes, and punctuation. It does not remove or validate raw TeX commands. An attacker who can influence the input document can consequently inject TeX primitives or package commands into the compilation process. Depending on the host's TeX security configuration, injected TeX may attempt to read files accessible ...[truncated 2160 chars]- Remediation
View remediation
